July Patch Tuesday Unveils 137 Vulnerabilities: What You Need to Know

Published:

spot_img

Microsoft Security Updates: Key Vulnerabilities and Patches

Microsoft has acknowledged a recently disclosed vulnerability, but there are no reports of it being exploited in the wild. This acknowledgment comes as part of the Patch Tuesday updates on July 8, marking the tenth consecutive month without any zero-day vulnerabilities reported as critical at the time of their publication. This month’s patch round includes 11 critical remote code execution (RCE) vulnerabilities, although three browser vulnerabilities released earlier in the month are not part of this total.

Recent SQL Server Vulnerabilities and Patches

It’s been a relatively quiet period regarding SQL Server updates, but Microsoft recently released a patch for CVE-2025-49719. This is an information disclosure vulnerability that affects all SQL Server versions back to 2016. Microsoft classifies this vulnerability as important rather than critical. Notably, older SQL Server versions that qualify for the Extended Security Update (ESU) program are not receiving patches. The advisory bluntly indicates that any version not listed is no longer supported, suggesting that organizations using unlisted versions should take immediate action. For those with ESU subscriptions, there’s hope that today’s vulnerabilities stem from the SQL Server 2016 codebase.

Interestingly, the advisory notes that CVE-2025-49719 has been publicly disclosed, with a Microsoft researcher credited for reporting it. This suggests that Microsoft is aware of additional public information about the vulnerability. True to form, SQL Server security advisories typically provide extensive FAQs to help administrators navigate various SQL Server versions. However, they often gloss over the specifics of the vulnerabilities themselves. The potential consequences of a successful exploit include the exposure of uninitialized memory, which might not yield valuable information immediately but could, in theory, lead to the compromise of sensitive data like cryptographic keys.

Critical Remote Code Execution (RCE) Vulnerabilities

Among the critical vulnerabilities released this month is CVE-2025-47981, which presents an RCE risk within the way Windows clients and servers negotiate authentication mechanisms. This flaw is tied to the Simple and Protected GSS-API Negotiation Mechanism (SPNEGO), which includes an extension developed by Microsoft known as NEGOX. The advisory clarifies that the vulnerability impacts any Windows client machine running Windows 10 version 1607 or later.

Patches are available for all current Windows Server versions; however, immediate exploitation of these servers may be limited. This limitation primarily stems from the group policy setting that allows certain authentication requests, which is generally only enabled on client machines. Domain-joined client assets might also have similar mitigation strategies in place since the applicable group policy is often disabled in that context. Regardless, patching all Windows assets is recommended due to the pre-authentication RCE risk, especially within privileged environments where exploitation is deemed more likely.

Comparison with Previous Vulnerabilities

For those familiar with Windows KDC Proxy servers, CVE-2025-49735 may resonate as it shares similarities with last month’s CVE-2025-33071. This unauthenticated critical RCE vulnerability underscores the continuous security challenges facing Windows environments.

Furthermore, SharePoint administrators should take note of CVE-2025-49704, which allows attackers with some existing SharePoint privileges to remotely execute code on the SharePoint server. The advisory indicates that elevated privileges are not technically required for exploitation, yet it mentions that the minimum privilege level is a site owner. This complexity suggests an inconsistency worth investigating, and, given the low difficulty of exploitation, immediate patching is advised.

End of Support for SQL Server 2012

In product lifecycle news, the ESU program for SQL Server 2012 has officially concluded, which means no future security patches will be available for this version, even for critical vulnerabilities. While Microsoft sometimes releases updates for obsolete products addressing severe vulnerabilities, relying on this practice is not a sound security strategy. The Visual Studio 2022 17.8 LTSC channel is also reaching its end, though newer LTSC versions are still available.

At present, Microsoft has retracted all the security advisories initially released in June 2025. This appears to be an inadvertent act, and it’s anticipated that these advisories will be restored in the near future.

With numerous vulnerabilities highlighted, it’s crucial for organizations to stay updated and proactive in implementing these patches to ensure their systems remain secure.

spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...